Re: PPP & Shell user (fwd)

MIX System Operator (sysop@mixcom.com)
Thu, 20 Jun 1996 06:18:57 -0500

At 01:28 PM 6/19/96 -0500, Robert Hof wrote:
>At 01:22 PM 6/17/96 -0700, MegaZone wrote:
>>Once upon a time Pat McClanahan shaped the electrons to say...
>>>In the raddb/users file how can I allow the user to specify which one
>>>they want to use - PPP or shell. I am trying to ge by with giving them on
>>>userid.
>>
>>You need to use the SCP patch on RADIUS 1.16 to use one UID. RADIUS 2.0
>>will make this much easier.
>>
>
>Pardon me for butting in here, but what am I doing wrong? (??right??) I'm
>using BSDI, and standard Livingston RADIUS. I have the ports set to
>Network/Login, and if a person logs in with a PAP/PPP connect, they get a
>Network connection. Otherwise, they rlogin to our user box. What's the
>problem with this? Works great for us.

Let's see, you have to enable rlogin in inetd.conf and anyone can call and
try to get in with that. Sure they won't get far, but they could keep calling.

Do you filter out 512, 513, and 514 at the router? Have you commented out
the unused ports in inetd.conf?

Script files are what control whether you can telnet or ftp to our system.
Users are assinged a script that allows the services they ordered.

My $0.02 opinion on the way to do it.
------------
Jeff Mountin
sysop@mixcom.com

MIX Communications
Serving the Internet since 1990

Sure my business card says "Senior Network Administrator"
They still make me do just about anything.